Privacy Policy
Last updated: July 2026
Overview
Infiforge operates the central identity provider and monitoring hub for the Infiforge ecosystem. We are designed around a privacy-first principle: we collect the minimum information necessary to run the service, we never sell your data, and you always know what is collected and why.
Information We Collect
We collect the minimum information necessary to provide the identity and monitoring services:
- Identity information: When you create an identity, we collect your email address and/or phone number, and a username. If you use passwords, they are hashed with Argon2. If you use passkeys, only your public key is stored — your private key never leaves your device.
- Linked provider information: If you link Google, Microsoft, or Apple, we store a reference to that provider and the identity it verified. OAuth tokens are encrypted at rest and never returned to your browser.
- Memberships and tenants: We store your memberships, roles, and tenant scoping across the services you join, so those services can honor your access.
- Audit events: We record authentication, consent, and authorization events in a tamper-evident audit trail. This includes timestamps, service identifiers, and outcome — not the content of your activity in any service.
- Usage data: We collect anonymized, aggregated data about system health and uptime to operate the monitoring hub. This cannot be linked to individual users.
Information We Do NOT Collect
We explicitly do not collect the following:
- The content of your activity inside any connected service
- Files, messages, or documents you create in connected services
- Your private passkeys or biometric data
- Raw passwords — only Argon2 hashes
- Tracking cookies or advertising identifiers
How We Use Information
The information we collect is used solely for:
- Providing secure sign-in and single sign-on across the ecosystem
- Enforcing your consent decisions and access memberships
- Operating the central monitoring hub and keeping services healthy
- Processing payments for paid subscriptions
- Sending service-related communications (passwordless links, billing notices, security alerts)
- Complying with legal obligations (if legally required and consistent with our commitments)
Data Sharing and Third Parties
We do not sell, rent, or share your personal information with third parties for their marketing purposes. We may share information with:
- Connected services: When you consent, we share only the identity attributes and scopes you approve with the service you are signing in to. Each service sees exactly what you authorized — nothing more.
- Identity providers: To verify your Google, Microsoft, or Apple sign-in, we interact with those providers per their own privacy policies. We never share data back to them.
- Payment processors: To process subscription payments. These processors are bound by data processing agreements and do not use your data for their own purposes.
- Infrastructure providers: We use cloud infrastructure for hosting. These providers have access to the data stored on their systems but are contractually prohibited from using it for any other purpose.
- Legal authorities: We will only disclose information if legally compelled by a valid court order or legal process.
Data Retention
We retain your identity information for as long as your identity is active. If you delete your identity, we delete your personal information within 30 days. Audit events are retained as required for security and compliance, typically 90 days to 7 years depending on the event type. Billing records are retained as required by applicable tax and financial regulations, but payment card numbers are not stored by us.
Security
We implement appropriate technical and organizational measures to protect your information, including: encryption at rest and in transit, Argon2 password hashing, RSA-signed JWTs verified via JWKS, encrypted OAuth tokens at rest, tamper-evident audit logs, regular security audits, and penetration testing. Core authentication and authorization libraries are open source for independent review.
Your Rights
Depending on your jurisdiction, you may have the right to:
- Access personal information we hold about you
- Request correction or deletion of your personal information
- Object to or restrict processing of your personal information
- Data portability
- Withdraw consent at any time (where processing is based on consent)
- Lodge a complaint with a data protection authority
To exercise these rights, contact us at support@infiforge.com.
Cookies
Our website and authentication service use cookies strictly necessary for sign-in and session management. We do not use tracking cookies, analytics cookies, or advertising cookies. You can configure your browser to refuse cookies, though this may affect sign-in functionality.
International Transfers
Infiforge operates globally. Your information may be processed in countries where our infrastructure providers maintain servers. We ensure appropriate safeguards are in place for international data transfers, including Standard Contractual Clauses where required.
Changes to This Policy
We may update this privacy policy from time to time. We will notify users of material changes via email and through the Infiforge application. Continued use of the service after changes constitutes acceptance of the updated policy.
Contact
If you have questions about this privacy policy or our data practices, contact us at support@infiforge.com.